216.73.217.22

CVE-2026-12043

· Published 12/06/2026 21:16 · Modified 12/06/2026 20:16 · Author: The MITRE Corporation

Labels: CVE-2026-12043 2026-06-12CVE-2026-12043CWE-415ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
12/06/2026 21:16
Modified
12/06/2026 20:16
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.8 HIGH (v3.1) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CWE-415
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
aws / aws-c-http cpe:2.3:a:aws:aws-c-http:0.11.0:*:*:*:*:*:*:*
aws / aws-c-http cpe:2.3:a:aws:aws-c-http:*:*:*:*:*:*:*:*

References